I have configured a Workload Rule but it doesn't work, I need all searches that last more than 3 minutes and are not from sc_admin to stop. I tested it in the laboratory and it worked, is there something wrong with my rule?
(search_type=adhoc) AND NOT (role=sc_admin) AND runtime>3m
Remember that I did a lab and the same rule worked.
Splunk Instance version: 9.0.2305.201
Laboratory: 9.1.2308.102
Can you help me please.
Make sure WLM is enabled and that there are no other rules with a higher priority that prevent this rule from executing.
Unfortunately it doesn't work, I configured the same rules in a working instance and it works.
Have you checked the _audit logs to confirm user and roles values?